Fault Tree Analysis · Chapter 7

References

The public standards and primary documents this topic draws on.

The public standards and handbooks this topic draws on. Every factual claim in the preceding chapters traces to one of these; the worked example's architecture, rates, intervals and results are illustrative teaching values and belong to no source.

The technique

  1. NUREG-0492, Fault Tree Handbook, US Nuclear Regulatory Commission, 1981 (the document that fixed the notation still in use: symbols, gates, construction rules, cut sets and the immediate cause concept).
  2. Fault Tree Handbook with Aerospace Applications, version 1.1, NASA Office of Safety and Mission Assurance, August 2002 (the modern, freely available treatment, and the source of the symbol table this module follows, including the combination gate, the conditioning event and the transfer convention).
  3. IEC 61025, Fault tree analysis (FTA) (the international standard for the technique itself, and the reference most non-aerospace sectors cite).
  4. W. E. Vesely, F. F. Goldberg, N. H. Roberts and D. F. Haasl, Fault Tree Handbook, 1981, and the subsequent literature on minimal cut set algorithms and importance measures (Birnbaum, Fussell-Vesely).

The process the tree lives in

  1. SAE ARP4761, Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment, 1996 (fault tree analysis inside the PSSA and SSA, the exposure-time forms for latent and sequenced failures, the equivalence of dependence diagrams and Markov analysis, and the reporting expected of a compliance fault tree).
  2. SAE ARP4761A / EUROCAE ED-135, December 2023 (the current edition; cite by edition, because the 1996 structure and numbering do not carry over).
  3. SAE ARP4754A / EUROCAE ED-79A, Guidelines for Development of Civil Aircraft and Systems, 2010, and ARP4754B / ED-79B, December 2023 (development assurance, and why a design error appears in a tree without a probability).

The objectives a tree is judged against

  1. 14 CFR § 25.1309, as amended by Amendment 25-152, 27 August 2024 (the rule: extremely improbable, and not from a single failure).
  2. FAA Advisory Circular 25.1309-1B, System Design and Analysis, 30 August 2024 (the probability bands, average probability per flight hour, at-risk time, and the guidance that a purely quantitative demonstration is generally not sufficient on its own).
  3. EASA Easy Access Rules for Large Aeroplanes (CS-25), AMC 25.1309 (the European statement of the same objectives).
  1. MIL-HDBK-338B, Electronic Reliability Design Handbook, US Department of Defense (fault tree analysis alongside the other reliability methods, for readers outside aviation).
  2. MIL-STD-882E, System Safety, US Department of Defense, 11 May 2012 (where fault trees sit in a defence programme's hazard analysis).
  3. NUREG/CR-5485, Guidelines on Modeling Common-Cause Failures in Probabilistic Risk Assessment, US Nuclear Regulatory Commission, 1998 (the beta-factor, alpha-factor and multiple Greek letter models, and how a dependent fraction is estimated and put into a model).

For the failure conditions a tree takes as its top events, see the functional hazard assessment module; for the item rates its basic events carry, the prediction references; for the mode ratios that turn an item into a set of basic events, the FMECA references.


Want to see this on a live system model? Request a walkthrough.